论文标题

2500 Docker Hub图像的脆弱性分析

Vulnerability Analysis of 2500 Docker Hub Images

论文作者

Wist, Katrine, Helsem, Malene, Gligoroski, Danilo

论文摘要

在过去的几年中,容器技术的使用猛增,Docker作为领先的容器平台。 Docker的在线存储库,用于公共容器图像,称为Docker Hub,在撰写本文时托管超过350万张图像,使其成为世界上最大的容器图像社区。我们对2500个Docker图像进行了广泛的漏洞分析。进行此类分析是特别有趣的,因为漏洞环境是一个快速变化的类别,漏洞扫描仪会不断开发和更新,发现了新的漏洞,并且Docker Hub上的图像量每天都在增加。我们的主要发现表明,(1)Docker Hub上新引入的漏洞的数量正在迅速增加; (2)经过认证的图像是最脆弱的; (3)官方图像是最不脆弱的; (4)漏洞数量和图像特征的数量(即,拉的数量,恒星数和自上次更新以来的天数)之间没有相关性; (5)最严重的漏洞起源于两种最受欢迎​​的脚本语言,即JavaScript和Python; (6)Python 2.X包装和Jackson-Databind套件的严重漏洞数量最多。我们认为我们的研究是过去几年中开放文献中发表的最广泛的脆弱性分析。

The use of container technology has skyrocketed during the last few years, with Docker as the leading container platform. Docker's online repository for publicly available container images, called Docker Hub, hosts over 3.5 million images at the time of writing, making it the world's largest community of container images. We perform an extensive vulnerability analysis of 2500 Docker images. It is of particular interest to perform this type of analysis because the vulnerability landscape is a rapidly changing category, the vulnerability scanners are constantly developed and updated, new vulnerabilities are discovered, and the volume of images on Docker Hub is increasing every day. Our main findings reveal that (1) the number of newly introduced vulnerabilities on Docker Hub is rapidly increasing; (2) certified images are the most vulnerable; (3) official images are the least vulnerable; (4) there is no correlation between the number of vulnerabilities and image features (i.e., number of pulls, number of stars, and days since the last update); (5) the most severe vulnerabilities originate from two of the most popular scripting languages, JavaScript and Python; and (6) Python 2.x packages and jackson-databind packages contain the highest number of severe vulnerabilities. We perceive our study as the most extensive vulnerability analysis published in the open literature in the last couple of years.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源